ai-inventory
EU AI Act per-system inventory — track each AI system's role (provider, deployer, importer,…
Fast "is this a problem?" answer for the quick Slack question — pattern-matches against your calibration. Use when the user says "is this a problem", "quick question", "can we do X", "do I need legal review for", "sanity check", or pastes a PM's question that needs a same-minute
$ npx -y skills add anthropics/claude-for-legal --skill is-this-a-problem --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/is-this-a-problemContext preview
The summary Claude sees to decide when to auto-load this skill.
Fast "is this a problem?" answer for the quick Slack question — pattern-matches against your calibration. Use when the user says "is this a problem", "quick question", "can we do X", "do I need legal review for", "sanity check", or pastes a PM's question that needs a same-minute
name: is-this-a-problem description: > Fast "is this a problem?" answer for the quick Slack question — pattern-matches against your calibration. Use when the user says "is this a problem", "quick question", "can we do X", "do I need legal review for", "sanity check", or pastes a PM's question that needs a same-minute fine / needs a look / hold call. argument-hint: "[the question]"
1. Load `~/.claude/plugins/config/claude-for-legal/product-legal/CLAUDE.md` → Risk calibration. 2. Apply the triage workflow below. 3. Pattern-match. Check for common traps. 4. Answer in one minute: ✅ Fine / ⚠️ Needs a look / 🛑 Hold. One sentence why. 5. If ⚠️ or 🛑: name the next step.
/product-legal:is-this-a-problem "Can we use customer logos on the pricing page?"
---
**Matter context.** Check `## Matter workspaces` in the practice-level CLAUDE.md. If `Enabled` is `✗` (the default for in-house users), skip the rest of this paragraph — skills use practice-level context and the matter machinery is invisible. If enabled and there is no active matter, ask: "Which matter is this for? Run `/product-legal:matter-workspace switch <slug>` or say `practice-level`." Load the active matter's `matter.md` for matter-specific context and overrides. Write outputs to the matter folder at `~/.claude/plugins/config/claude-for-legal/product-legal/matters/<matter-slug>/`. Never read another matter's files unless `Cross-matter context` is `on`.
---
Before producing output, check where it's going. If the user has named a destination (a channel, a distribution list, a counterparty, "everyone"), ask whether it's inside the privilege circle. Public channels, company-wide lists, counterparty/opposing counsel, vendors, and clients (for work product) waive the protection. When the destination looks outside the circle, flag it and offer (a) the privileged version for legal only, (b) a sanitized version for the broader channel, or (c) both — don't silently apply a privileged header and then help paste it somewhere the header won't protect it. See the canonical `## Shared guardrails → Destination check` in this plugin's CLAUDE.md.
Most "quick legal question" Slacks are one of three things: (a) not a problem, say so fast, (b) a real thing that needs a real look, route it, (c) a thing that looks fine but has a trap, catch the trap. This skill sorts in under a minute using the calibration table.
The goal is speed. The PM asked at 4:47pm. They want an answer, not a memo.
Read `~/.claude/plugins/config/claude-for-legal/product-legal/CLAUDE.md` → `## Risk calibration`. The whole point of this skill is pattern-matching against that table.
Does the question match a pattern in the calibration table?
**Matches "usually FYI":** → Say so. One line. "You're fine — [pattern]. Ship it."
**Matches "usually requires work":** → Name the work. "Needs a [PIA / vendor review / claims check]. Takes [timeline from table]. Want me to start it?"
**Matches "usually blocks":** → Stop them. "Hold on — [pattern]. This needs a real look before anyone commits to a date. Let's talk."
**Doesn't match anything:** → Say that too. "This doesn't pattern-match to anything I've seen here. Needs a human look — [your name] or me tomorrow?"
Some questions are fine on the surface but have a twist. Recognize the fact pattern, ask the catch question, then research the applicable doctrine for the specific fact pattern before concluding whether it's a problem or not.
| Question sounds like | Why it might not be simple | Catch it by asking | |---|---|---| | "Can we add [vendor] to the integration?" | Vendor touches a new data category — flag as potentially implicating privacy and vendor-risk regimes and route for research | "What data flows to them?" | | "Can we A/B test the pricing page?" | Differential pricing by segment can implicate consumer-protection and anti-discrimination regimes — flag and route for research | "Are both arms seeing the same price for the same thing? How are users assigned to arms?" | | "Can we auto-enroll users in the new feature?" | Default-on behavior for users who previously opted out can implicate consent and consumer-protection rules — flag and route for research | "Does this respect existing preferences?" | | "Can we use customer logos on the site?" | Logo use is a separate permission from the contract relationship — flag as potentially implicating publicity / endorsement rules and the customer's own contract terms | "What does the contract say about publicity? Do we have written permission?" | | "Can we train on this data?" | Usage rights for the original collection purpose may not extend to training — flag and research the notice/consent the users were given at collection | "What did we tell users when we collected it? What jurisdictions are the users in?" | | "It's just an internal tool" | Internal tools still process personal data — flag as potentially implicating privacy regimes and route for research | "Whose data does it touch? Employees, customers, third parties?" | | "We already do something similar" | "Similar" is doing a lot of work — the delta is where the issue usually is | "Similar how? What's actually different?" | | "Can we use [AI vendor / LLM] for this?" | Vendor AI terms may permit training on inputs; use case may need an AIA — flag and route to `/ai-governance-legal:use-case-triage` | "Is there an AI addendum? What data goes into the model?" | | "Can we add AI to this feature?" | May be a new use case not in the registry; may trigger AIA requirement — flag and route to `/ai-governance-legal:use-case-triage` | "What does the AI do — assistive or automated? Who does it act on?" | | "The model just decides automatically" | Automated decision-making without human review is regulated in some jurisdictions — flag and research the applicable r
Reference agents, skills, and data connectors for the legal workflows we see most — in-house commercial, privacy, product, corporate, employment, litigation, regulatory, AI governance, IP, and the learning side of the practice (law school clinics and
EU AI Act per-system inventory — track each AI system's role (provider, deployer, importer,…
Run an AI impact assessment — structured intake, risk analysis, regulatory classification per…
Run the cold-start interview — learns your AI governance practice and writes…
Guided customization of your AI governance practice profile — change one thing without…
Manage matter workspaces — new, list, switch, close, or detach (practice-level).…
Keep the AI policy current with practice — weekly sweep of saved AIAs, triage results, and…